UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

UC Browser for Android, Desktop Exposes 500M Users to MiTM Attacks

The extremely popular UC Browser and UC Browser Mini Android applications with a total of over 600 million installs expose their users to MiTM attacks by downloading and installing extra modules from their own servers using unprotected channels and bypassing Google Play’s servers altogether. Doctor Web’s security researchers also created a MiTM attack demo video (embedded below), showing how a potential victim wants to view a PDF document using UC Browser and has to download a plug-in module to do it from the app’s update servers. Doctor Web’s researchers also mention that the UC Browser Mini application which also comes with the same update mechanism that circumvents the official Play Store update channels to download extra app modules is not affected by the MiTM vulnerability.

Source: www.bleepingcomputer.com